In recent weeks, Cato Networks made clear it is deepening its position in AI security while building on its SASE foundation. The company launched Agentic Threat Prevention, disclosed two critical vulnerabilities in the Cursor IDE through its Cato AI Labs, and reported that annualized recurring revenue has now passed $415 million, up 42% year over year. For a large, privately held company, that growth rate stands out because it comes from the AI security side of the business and from large enterprise accounts choosing a single cloud-native platform over the stitched-together point products of an earlier era.

The centerpiece of the announcement is Cato Agentic Threat Prevention, a capability that deploys autonomous agents to predict likely attack paths and automatically tailor protections to each customer environment before AI-assisted attacks can advance. Cato argues that the speed of AI-assisted attacks outpaces traditional detect-and-respond models, so the platform combines network and security telemetry into a unified view and lets agents continuously adapt controls. It is a deliberate move to position the cloud-native SASE platform as the enforcement point for the emerging agentic threat landscape, and it reflects where Cato believes the security industry is headed rather than where it has been.
Cato’s research arm is backing that positioning with substance. Cato AI Labs disclosed two critical remote code execution vulnerabilities in the Cursor IDE, collectively named DuneSlide (CVE-2026-50548 and CVE-2026-50549), each scoring 9.8 on the CVSS scale. The flaws abuse zero-click prompt injection via web searches or MCP servers to escape the IDE’s sandbox and achieve full system-level code execution, a real risk given that, per Cursor, the tool is used by more than half of the Fortune 500. Cursor patched both issues in 3.0, released in early April. Alongside the disclosure, Cato published research on the agentic attacker showing how offensive capability increasingly comes from the full agentic stack—a frontier model, agent platform, MCP tooling, and operating context—rather than the underlying model alone, and how that shifts the defensive challenge for enterprises.
The strongest signal in this update is the AI security customer wins, which underscore how Cato is winning in the enterprise rather than just adding seats. One large global financial company, which had to secure AI usage across roughly 50,000 employees, chose Cato for AI security across browsers, APIs, gateways, IDEs, and applications through a single policy engine—displacing Zscaler—while retaining its AI prompt and response data in its own controlled environment. Another large financial services company selected Cato to protect roughly 15,000 AI users and 15,000 AI applications ahead of a production launch, displacing Netskope, to keep sensitive client data from reaching third-party AI models across internal development, customer-facing applications, and machine-to-machine financial workflows. These are the kind of brands that validate a strengthening position in the AI security market, not simply in SASE.
On Bloomberg Tech earlier this week, Cato CEO Shlomo Kramer framed the company’s trajectory around clients shifting from buying security products to adopting a single platform solution, with multi-million-dollar deals in the first half of the year and what he described as a “do or die” security innovation imperative in the AI threat landscape. Cato now serves more than 4,800 customers, with Q2 enterprise momentum across manufacturing, robotics, telecom, and data analytics. We believe Cato is growing meaningfully faster than the broader SASE market, and its recent product releases and research signal a clear pivot to agentic AI security. Importantly, this is not a separate architecture being built alongside SASE; Cato is leveraging the same cloud-native platform, telemetry, policy and enforcement capabilities as AI security becomes a larger enterprise requirement. Its exposure to large enterprise customers will help sustain that momentum. 650 Group researches several of the technologies we covered in this blog, including Enterprise and Security and SASE.